PAXVIAN · TRUST
Subprocessors and retention
This page identifies service providers Paxvian may use and the proposed Business retention schedule. A provider is active only when its feature is configured. The signed DPA controls a contracted customer's exact schedule.
Service providers
Hosting and durability: Render for application hosting and Cloudflare R2 for encrypted off-host replication when configured.
Transactional services: the configured SMTP provider for email; iyzico, Stripe or Shopier for hosted payment when enabled. Card data stays on the payment provider's hosted surface.
Optional intelligence sources: Brave Search or Tavily, GitHub API, GDELT, XposedOrNot or Have I Been Pwned, and Anthropic. Paxvian sends only the minimized query or structured evidence needed for the enabled feature.
Business retention schedule
Raw topology and configuration inputs are retained through report acceptance, then deleted within 30 days unless the customer approves a written extension. Normalized evidence stays for the contract term plus 90 days. Generated reports stay for the contract term plus 12 months. Security and authorization audit records stay for 12 months. Encrypted backups use a rolling 30-day expiry after primary deletion. Invoice and tax records follow the statutory period.
Send deletion and subprocessor questions to info@paxvian.com.